Microsoft-linked reporting says North Korean threat actors are using AI to scale and refine long-running “fake IT worker” schemes, where operatives pose as legitimate remote hires to obtain authorized access inside victim organizations. The activity is attributed to DPRK-linked clusters Jasper Sleet and Coral Sleet, with AI used to improve identity fabrication and maintenance (including face/voice manipulation) and to sustain day-to-day communications that help keep fraudulent personas credible, enabling “sustained, large-scale misuse of legitimate access.”
Separately, reporting on suspected DPRK-linked intrusions describes a coordinated campaign against cryptocurrency organizations spanning staking platforms, exchange software providers, and exchanges, with theft of source code, private keys, and cloud secrets. Investigators described two primary access paths: exploitation of CVE-2025-55182 in the React2Shell framework (including mass scanning and WAF-bypass techniques) and the use of pre-obtained valid AWS access tokens to move directly into cloud enumeration; researchers also recovered artifacts from attacker infrastructure (e.g., shell history, archived code, and tool configurations) that provided visibility into post-compromise activity and C2 setup.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft Threat Intelligence reported that North Korean-linked actors are using AI to improve fake IT worker scams, including generating application materials, maintaining personas, manipulating profile imagery and identity documents, and using voice-changing tools. The report also said Coral Sleet was experimenting with agentic AI to automate parts of attack workflows such as infrastructure provisioning and payload deployment.
A coordinated intrusion campaign targeted staking platforms, exchange software providers, and exchanges using two main access paths: exploitation of CVE-2025-55182 in the React2Shell framework and separate intrusions using pre-obtained valid AWS access tokens. The attackers stole source code, private keys, cloud secrets, Terraform state data, Kubernetes secrets, and container images from affected environments.
Over a two-week period in January 2026, researchers from Ctrl-Alt-Intel discovered exposed open directories containing attacker artifacts tied to a coordinated campaign against cryptocurrency firms. The materials included shell history, archived source code, and tool configurations that helped reveal the operation's methods and targets.
North Korean-linked operators conducted long-running "fake IT worker" scams in which they fraudulently obtained jobs at organizations and then abused the legitimate access those roles provided. Microsoft later associated this activity with the Jasper Sleet and Coral Sleet clusters.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.